Monday Myth: Every Failure Needs Someone Responsible
When the de Havilland Comet entered commercial service in 1952, it appeared to have compressed the future into an aluminium fuselage. It flew higher, faster and more smoothly than the piston-powered airliners it replaced. Its four jet engines disappeared into the wings rather than hanging beneath them. Its pressurised cabin allowed passengers to travel above much of the weather, surrounded by large windows and a degree of comfort that made earlier aircraft feel suddenly obsolete.
The Comet did not merely improve air travel. It changed what an airliner could mean.
That achievement came with an engineering problem that aviation had not yet encountered at such scale. Every flight required the cabin to expand slightly as it climbed and contract as it descended. The pressure difference remained well within the aircraft’s static strength, but an airframe does not experience a career as one continuous load. It experiences thousands of cycles. Static strength describes the ability to resist a load applied once. It says much less about what repeated loading does over time. A structure capable of resisting a force once may still accumulate microscopic damage when subjected to a smaller force repeatedly.
This distinction would eventually transform aircraft design. In the early 1950s, however, engineers were advancing into territory where operational experience remained thin. The Comet did not simply use new engines. It combined high-altitude pressurisation, new structural demands, new manufacturing techniques and an economic need to operate regular commercial services. Each element appeared manageable in isolation. Their interaction had not yet written its history.
The Aircraft That Passed Its Tests
De Havilland had not ignored structural safety. Its engineers tested the Comet fuselage beyond the requirements of the period. The aircraft’s working pressure difference measured approximately 8.25 pounds per square inch. Contemporary rules required proof testing, which deliberately loads a structure beyond normal operating conditions to demonstrate its reserve strength, to 1.33 times that pressure. De Havilland tested to twice the working pressure. The company also conducted thousands of pressurisation cycles on a prototype fuselage, eventually reaching a result that appeared to demonstrate a comfortable fatigue life.
This evidence mattered because engineering depends upon evidence gathered under controlled conditions. Calculations describe expected behaviour. Tests expose the structure to reality. When both agree, confidence becomes rational.
Yet the same fuselage had served two different purposes. Engineers first subjected it to unusually high pressures for proof testing and subsequently used it for fatigue testing. The initial overpressure changed the material around the areas of highest stress. It effectively cold-worked parts of the aluminium, permanently deforming the material around the most highly stressed areas and changing how subsequent fatigue cracks would develop.
The test had not failed to measure the specimen. It had measured it accurately. The specimen no longer represented the production aircraft.
That difference remained invisible because the result looked conservative. Testing beyond the regulatory requirement suggested greater caution, not greater risk. More pressure appeared to produce stronger evidence. The test programme therefore carried the persuasive shape of engineering rigour while concealing an interaction between two valid procedures. Neither test made sense without understanding what the previous test had done to the material.
Production aircraft never received this accidental strengthening. They entered service with a fatigue life profoundly different from the one demonstrated by the prototype.
A Failure Without a Witness
On 10 January 1954, Comet G-ALYP departed Rome for London. While climbing through approximately 27,000 feet, communication ceased in the middle of a transmission. The aircraft broke apart above the Mediterranean near Elba, killing all thirty-five people aboard.
Investigators initially considered numerous possibilities: engine failure, fire, control flutter, explosive decompression, structural overload and severe atmospheric conditions. Control flutter describes a self-reinforcing aerodynamic vibration. The wreckage lay beneath the sea, scattered across an area that the investigators could not yet define because they did not know the sequence of failure. They needed the wreckage to understand the accident, but they needed an understanding of the accident to know where to search for the wreckage.
The fleet returned to service after extensive modifications intended to cover the plausible causes. On 8 April, another Comet disappeared near Naples. The similarity removed much of the remaining comfort. Something fundamental remained inside the system.
At the Royal Aircraft Establishment in Farnborough, investigators placed another Comet fuselage inside an enormous water tank. Water allowed them to pressurise the structure without storing the destructive energy that compressed air would have released during a rupture. They repeatedly filled and relieved the cabin pressure, reproducing the mechanical rhythm of flight while hydraulic actuators simulated aerodynamic loads on the wings.
After the equivalent of roughly 3,060 pressurised flights, the fuselage ruptured at the corner of a forward escape hatch. That failure redirected the search at Elba. Investigators recovered the section containing the Automatic Direction Finder apertures on the roof of G-ALYP and found the signature of fatigue around one of them. A crack had grown under repeated pressurisation until the remaining structure could no longer contain the cabin load.
The popular retelling often reduces the disaster to square passenger windows. The actual investigation proved less convenient. Window and aperture geometry created stress concentrations, but the initiating fracture on G-ALYP emerged around an ADF opening on the roof. Manufacturing details, rivet holes, local stresses, pressure cycles, structural assumptions and unrepresentative testing combined to produce the failure. The rupture had a location. The accident had a system. The two should not be confused. The FAA’s reconstruction of the investigation preserves this distinction particularly well.
Henry Petroski later made this relationship between failure and knowledge central to To Engineer Is Human. Engineering progresses not because failure possesses some intrinsic virtue, but because failure reveals the limits of the assumptions embedded in successful designs. Success confirms that a structure survived the conditions it encountered. It cannot prove that the structure will survive conditions that its designers misunderstood, omitted or had not yet imagined. Failure supplies information that ordinary operation withholds. The Comet disasters did not demonstrate that its engineers had abandoned rigour. They revealed that rigour itself remains bounded by the questions engineers know how to ask.
The Seduction of the Crack
Every fracture has a point at which it becomes visible. This physical fact encourages a dangerous intellectual shortcut: if the structure opened there, that location must contain the cause.
Fracture mechanics, the study of how cracks initiate and propagate through loaded materials, says otherwise. A crack tip concentrates stress, but the tip does not explain why the material carried that stress, why the geometry concentrated it, why repeated loads enlarged it, why inspection failed to reveal it or why the assumed service life exceeded the actual one. The final rupture merely identifies the place where the accumulated history of the structure could no longer remain hidden.
Organisations also reveal their failures at specific points. A deployment breaks production. An engineer approves the change. A manager misses a warning. A salesperson promises an impossible date. An operator enters the wrong value. A team releases a feature without considering an obscure dependency. The incident therefore arrives with something the Comet investigation initially lacked: a visible human standing beside the rupture.
The search for causality can then end before it has begun.
The individual closest to the event offers an explanation that feels complete because it restores a familiar moral order. Someone acted. The action preceded the failure. Had the person acted differently, the immediate event might not have occurred. Each statement may remain factually correct while explaining almost nothing about the system that made the action consequential.
The engineer approved a dangerous deployment because the approval process had gradually become ceremonial. The manager missed a warning because every operational concern carried the same declared priority. The salesperson promised the date because revenue recognition rewarded commitment while delivery absorbed the uncertainty. The operator entered the wrong value because the interface accepted an impossible state. The team overlooked the dependency because the architecture distributed responsibility more effectively than it distributed knowledge.
The person remains involved. Human agency does not disappear merely because the system has structure. Yet involvement, culpability and causality describe different properties. Organisations often merge them because assigning a name costs less than reconstructing a system.
Responsibility Produces a Satisfying Report
A named failure owner gives management a sense of completion. The incident acquires boundaries. The accountable person receives feedback, training or removal. A process gains another approval. The report closes.
This mechanism does not merely protect senior leaders from discomfort. It solves several organisational problems at once. It makes the event legible to governance. It converts a distributed interaction into an individual record. It demonstrates decisiveness. It prevents an investigation from reaching commercial incentives, overloaded portfolios, architectural debt or decisions made several levels above the operational rupture.
Most importantly, it preserves the belief that the system works when people follow it correctly.
That belief resembles the confidence created by the Comet’s 16,000-cycle test result. The evidence looks strong because the test has already conditioned the specimen. In organisations, people learn how incidents get judged long before the next incident occurs. They adapt their behaviour accordingly. They document compliance, request defensive approvals, narrow their ownership and avoid decisions whose benefits remain collective while the risks remain personal.
The organisation then tests a population already shaped by its accountability system.
Under these conditions, the absence of reported failure does not demonstrate operational health. It may demonstrate that people have learnt which anomalies should remain local, which uncertainties should never enter a written record and which decisions require enough participants to make authorship impossible. Responsibility does not disappear. It diffuses into meetings while authority retreats into process.
The resulting organisation looks increasingly controlled. It also knows progressively less about itself.
When Accountability Removes Information
A complex system depends upon weak signals. Near misses, unexpected latency, awkward workarounds and small deviations reveal where operating conditions have begun to diverge from design assumptions. None carries the drama of a production outage. Their value comes precisely from arriving before the structure opens.
Punitive accountability changes the economics of reporting them. The person who reveals a weakness risks becoming associated with it, while the benefit of disclosure spreads across the organisation. Silence offers private safety. Transparency offers collective safety. Rational individuals soon learn which one the system rewards.
That change creates a second-order failure. Leaders receive cleaner reports and conclude that additional control has improved performance. In reality, the measurement system has lost sensitivity. The organisation resembles an aircraft whose strain gauges, sensors that measure structural deformation, have been disconnected because their readings disturbed the passengers.
More approvals rarely correct this. They distribute permission without distributing understanding. Each reviewer sees a fragment and assumes that someone else owns the whole. When failure eventually occurs, the number of approvals proves only that the decision travelled through the coordination system. It says little about whether anyone could still reconstruct the productive system beneath it.
AI can accelerate this deterioration. It can generate more complete incident reports, classify causes, identify policy deviations and recommend controls with impressive consistency. Yet if the organisation asks a culprit-shaped question, the technology will return a culprit-shaped answer more efficiently. Automation increases the speed with which the existing model converts ambiguity into administrative certainty.
The report improves. The investigation disappears.
The Difference Between Owning and Causing
Accountability still matters. Systems without ownership decay into ambiguity, deferred maintenance and collective excuses. The phrase “systemic failure” can become a sophisticated way of claiming that nobody could have acted differently. That conclusion proves no more useful than blaming the last person who touched the system.
The distinction lies elsewhere.
Causality looks backwards and reconstructs how conditions interacted. Accountability looks forwards and determines who now carries the authority and obligation to change those conditions. One investigation may identify dozens of causal contributors while still producing clear ownership. Conversely, an organisation may identify one responsible individual while leaving every causal mechanism intact.
This explains why replacing a person often fails to prevent recurrence. The successor inherits the same incentives, information boundaries, queues, interfaces and economic pressures. The new individual may exercise greater caution, but caution inside an unchanged system usually becomes delay. Eventually the organisation interprets that delay as insufficient ownership and searches for someone more decisive.
The system therefore alternates between rewarding action and punishing its consequences. Every new occupant discovers the contradiction independently.
The Comet investigation did not need the name of the worker who formed a particular rivet hole in order to transform aviation. It needed to understand pressure cycles, stress concentration, representative testing, crack propagation and the limits of calculating a component’s safe operating life before fatigue made replacement necessary. The resulting knowledge changed window geometry, structural testing and eventually the industry’s approach to designing aircraft capable of continuing to operate safely with limited damage between inspections.
The rupture at the ADF aperture remained physically real. It simply ceased to serve as a complete explanation.
Organisations frequentThe report improves. The investigation disappears.ly demand a name because names allow them to close events that systems thinking would force them to reopen. Somewhere in the resulting action log, a person receives additional training, an approval box appears in the workflow, and the original conditions continue cycling under pressure.
The structure becomes silent again.
For a while.
Member discussion